2021 CVE Vulnerabilities

23,448 CVEs published in 2021.

Filter:HIGHClear
CVE IDSeverityCVSSDescription
CVE-2021-3546HIGH8.2An out-of-bounds write vulnerability was found in the virtio vhost-user GPU device (vhost-user-gpu) of QEMU in versions ...
CVE-2021-24012HIGH7.3An improper following of a certificate's chain of trust vulnerability in FortiGate versions 6.4.0 to 6.4.4 may allow an ...
CVE-2021-23895HIGH8Deserialization of untrusted data vulnerability in McAfee Database Security (DBSec) prior to 4.8.2 allows a remote authe...
CVE-2021-23894HIGH8.8Deserialization of untrusted data vulnerability in McAfee Database Security (DBSec) prior to 4.8.2 allows a remote unaut...
CVE-2021-29090HIGH7.2Improper neutralization of special elements used in an SQL command ('SQL Injection') vulnerability in PHP component in S...
CVE-2021-32656HIGH8.6Nextcloud Server is a Nextcloud package that handles data storage. A vulnerability in federated share exists in versions...
CVE-2021-31684HIGH7.5A vulnerability was discovered in the indexOf function of JSONParserByteArray in JSON Smart versions 1.3 and 2.4 which c...
CVE-2021-22123HIGH8.8An OS command injection vulnerability in FortiWeb's management interface 6.3.7 and below, 6.2.3 and below, 6.1.x, 6.0.x,...
CVE-2021-32924HIGH8.8Invision Community (aka IPS Community Suite) before 4.6.0 allows eval-based PHP code injection by a moderator because th...
CVE-2021-3516HIGH7.8There's a flaw in libxml2's xmllint in versions before 2.9.11. An attacker who is able to submit a crafted file to be pr...
CVE-2021-3495HIGH8.8An incorrect access control flaw was found in the kiali-operator in versions before 1.33.0 and before 1.24.7. This flaw ...
CVE-2021-3412HIGH7.3It was found that all versions of 3Scale developer portal lacked brute force protections. An attacker could use this gap...
CVE-2021-33184HIGH7.7Server-Side request forgery (SSRF) vulnerability in task management component in Synology Download Station before 3.8.15...
CVE-2021-33183HIGH7.9Improper limitation of a pathname to a restricted directory ('Path Traversal') vulnerability container volume management...
CVE-2021-32027HIGH8.8A flaw was found in postgresql in versions before 13.3, before 12.7, before 11.12, before 10.17 and before 9.6.22. While...
CVE-2021-29740HIGH7.8IBM Spectrum Scale 5.0.0 through 5.0.5.6 and 5.1.0 through 5.1.0.3 system core component is affected by a format string ...
CVE-2021-29665HIGH7.8IBM Security Verify Access 20.07 is vulnerable to a stack based buffer overflow, caused by improper bounds checking whic...
CVE-2021-29092HIGH8.8Unrestricted upload of file with dangerous type vulnerability in file management component in Synology Photo Station bef...
CVE-2021-29088HIGH7.8Improper limitation of a pathname to a restricted directory ('Path Traversal') in cgi component in Synology DiskStation ...
CVE-2021-24312HIGH7.2The parameters $cache_path, $wp_cache_debug_ip, $wp_super_cache_front_page_text, $cache_scheduled_time, $cached_direct_p...
CVE-2021-24311HIGH8.8The wp_ajax_upload-remote-file AJAX action of the External Media WordPress plugin before 1.0.34 was vulnerable to arbitr...
CVE-2021-20576HIGH7.5IBM Security Verify Access 20.07 could allow a remote attacker to send a specially crafted HTTP GET request that could c...
CVE-2021-23019HIGH7.8The NGINX Controller 2.0.0 thru 2.9.0 and 3.x before 3.15.0 Administrator password may be exposed in the systemd.txt fil...
CVE-2021-23017HIGH7.7A security issue in nginx resolver was identified, which might allow an attacker who is able to forge UDP packets from t...
CVE-2021-23018HIGH7.4Intra-cluster communication does not use TLS. The services within the NGINX Controller 3.x before 3.4.0 namespace are us...

Check if your code is affected by 2021 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now